<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T17:25:39.742547+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2022:7519</id>
    <title>ALSA-2022:7519 — Moderate: grafana security, bug fix, and enhancement update</title>
    <updated>2026-10-02T17:25:40.013646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: grafana</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>The following packages have been upgraded to a later upstream version: grafana (7.5.15). (BZ#2055348)</p>
<p>Security Fix(es):</p>
<p>* sanitize-url: XSS due to improper sanitization in sanitizeUrl function (CVE-2021-23648)
* golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)
* golang: go/parser: stack exhaustion in all Parse* functions (CVE-2022-1962)
* grafana: Forward OAuth Identity Token can allow users to access some data sources (CVE-2022-21673)
* prometheus/client_golang: Denial of service using InstrumentHandlerCounter (CVE-2022-21698)
* grafana: XSS vulnerability in data source handling (CVE-2022-21702)
* grafana: CSRF vulnerability can lead to privilege escalation (CVE-2022-21703)
* grafana: IDOR vulnerability can lead to information disclosure (CVE-2022-21713)
* golang: encoding/xml: stack exhaustion in Decoder.Skip (CVE-2022-28131)
* golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)
* golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
* golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)
* golang: encoding/xml: stack exhaustion in Unmarshal (CVE-2022-30633)
* golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)
* golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)</p>
<p>For more details about the security issue(s), including…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2022:7519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02596</id>
    <title>bdu:2024-02596</title>
    <updated>2026-10-02T17:25:40.013771+00:00</updated>
    <content>bdu:2024-02596</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02596"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2022-21673</id>
    <title>BIT-grafana-2022-21673 — OAuth Identity Token exposure in Grafana</title>
    <updated>2026-10-02T17:25:40.013799+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2022-21673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-06890</id>
    <title>cnvd-2022-06890</title>
    <updated>2026-10-02T17:25:40.013841+00:00</updated>
    <content>cnvd-2022-06890</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-06890"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-234503</id>
    <title>EUVD-2026-234503</title>
    <updated>2026-10-02T17:25:40.013866+00:00</updated>
    <content>EUVD-2026-234503</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-234503"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-21673</id>
    <title>fkie_cve-2022-21673</title>
    <updated>2026-10-02T17:25:40.013891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-21673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-21673</id>
    <title>gsd-2022-21673</title>
    <updated>2026-10-02T17:25:40.013938+00:00</updated>
    <content>gsd-2022-21673</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-21673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2022-1531</id>
    <title>OESA-2022-1531 — grafana security update</title>
    <updated>2026-10-02T17:25:40.013958+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: grafana, openEuler:20.03-LTS-SP2: grafana, openEuler:20.03-LTS-SP3: grafana</p>
<p>Metrics dashboard and graph editor.

Security Fix(es):

Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.(CVE-2022-21673)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2022-1531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:11816-1</id>
    <title>openSUSE-SU-2024:11816-1 — grafana-8.3.4-1.1 on GA media</title>
    <updated>2026-10-02T17:25:40.014020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-8.3.4-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:11816-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2022:0056</id>
    <title>RHSA-2022:0056 — Red Hat Security Advisory: OpenShift Container Platform 4.10.3 security update</title>
    <updated>2026-10-02T17:25:40.014057+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>gogo/protobuf: plugin/unmarshal/unmarshal.go lacks certain index validation nodejs-axios: Regular expression denial of service in trim function grafana: Snapshot authentication bypass golang: archive/zip: Reader.Open panics on empty string grafana: directory traversal vulnerability golang: net/http: limit growth of header canonicalization cache golang: syscall: don't close fd 0 on ForkExec error grafana: Forward OAuth Identity Token can allow users to access some data sources</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2022:0056"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1</id>
    <title>SUSE-FU-2022:1419-1 — Feature update for grafana</title>
    <updated>2026-10-02T17:25:40.014105+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Feature update for grafana</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-fu-2022:1419-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21673</id>
    <title>UBUNTU-CVE-2022-21673</title>
    <updated>2026-10-02T17:25:40.014136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retrieve data for which they may not have intended access. This attack relies on the Grafana instance having data sources that support the Forward OAuth Identity feature, the Grafana instance having a data source with the Forward OAuth Identity feature toggled on, the Grafana instance having OAuth enabled, and the Grafana instance having usable API keys. This issue has been patched in versions 7.5.13 and 8.3.4.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-21673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0406</id>
    <title>WID-SEC-W-2022-0406 — Grafana: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
    <updated>2026-10-02T17:25:40.014173+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Grafana ausnutzen, um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0406"/>
  </entry>
</feed>
